VDB
Sign up
HIGH

GHSA-hqjg-pww4-pcgq

@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

Quick fix

GHSA-hqjg-pww4-pcgq — @google/clasp: upgrade to the fixed version with the command below.

npm install @google/clasp@3.2.0

Details

### Impact Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.

### Patches Fixed in version 3.2.0

### Workarounds * Only clone or pull scripts from trusted sources * Review the output of the `pull` and `clone` commands to verify only expected project files are modified

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@google/clasp
Introduced in: 0Fixed in: 3.2.0
Fixnpm install @google/clasp@3.2.0

References